CVE-2024-1304

MEDIUM

Badger Meter Monitool < 4.7 - Cross-Site Scripting

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-1304. PoCs published by guillermogm4.

AI-analyzed exploit summary This repository contains a functional proof-of-concept for CVE-2024-1304, demonstrating an unauthenticated reflected XSS vulnerability in Badgermeter moni:tool version 4.6.3. The exploit involves injecting arbitrary JavaScript via the URL path.

Description

Cross-site scripting vulnerability in Badger Meter Monitool that affects versions up to 4.6.3 and earlier. This vulnerability allows a remote attacker to send a specially crafted javascript payload to an authenticated user and partially hijack their browser session.

Exploits (1)

nomisec WORKING POC
by guillermogm4 · poc
https://github.com/guillermogm4/CVE-2024-1304---Badgermeter-moni-tool-Reflected-Cross-Site-Scripting-XSS

This repository contains a functional proof-of-concept for CVE-2024-1304, demonstrating an unauthenticated reflected XSS vulnerability in Badgermeter moni:tool version 4.6.3. The exploit involves injecting arbitrary JavaScript via the URL path.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Badgermeter moni:tool version 4.6.3
No auth needed
Prerequisites: Access to the target device's web interface
MITRE ATT&CK
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Scores

CVSS v3 6.3
EPSS 0.0067
EPSS Percentile 47.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
badgermeter/monitool < 4.7
Published Mar 12, 2024
Tracked Since Feb 18, 2026